# React Server Components DoS Vulnerability (CVE-2026-23870) Lets Attackers Freeze Next.js Servers With a Single POST Request

> CVE-2026-23870 is an unauthenticated denial-of-service flaw (CWE-400/CWE-770) in the React Server Components packages react-server-dom-webpack, react-server-dom-turbopack and react-server-dom-parcel. A crafted ~900 KB multipart POST to a Server Function endpoint forces quadratic form-data processing that blocks the Node.js event loop. Fixed in React 19.0.6, 19.1.7 and 19.2.6; a public PoC exists but no in-the-wild exploitation is reported.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T13:20:01.672Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3096
- **ID:** TL-2026-3096
- **Severity:** HIGH (CVSS 7.5)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 12 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-23870

## Description

CVE-2026-23870 affects the React Server Components (RSC) server-side packages react-server-dom-webpack, react-server-dom-turbopack and react-server-dom-parcel in React 19.0.0-19.0.5, 19.1.0-19.1.6 and 19.2.0-19.2.5. The CVE was assigned by Meta and carries a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The advisory (GHSA-rv78-f8rc-xrxh) lists CWE-400 and CWE-770; Red Hat classifies it as CWE-770. Applications are exposed only if they run server-side React code through a framework or bundler that supports React Server Components (for example Next.js, React Router, Waku, @parcel/rsc, @vitejs/plugin-rsc, rwsdk).

Root cause (per researcher Simon Koeck's write-up): when React rebuilds form data for a Server Action/Server Function request, it resolves each $K pointer (a reference marker for a nested form) by walking the entire list of request fields and matching names against a prefix. There was no cap on either the number of pointers or the number of fields, so the cost is quadratic. A request with 10,000 $K pointers and 10,000 filler fields forces about 100 million string comparisons.

Proof of concept: the payload uses 10,000 $K pointers nested one level deep, which avoids the argument-count limits. They sit under $ACTION_0:2 to avoid the nesting-depth restrictions, and are paired with 10,000 filler fields. The total request is about 900 KB. The attacker needs no authentication; the Server Action ID can be extracted from the target's served HTML/JavaScript. Reported impact: about 4 seconds of server freeze for a single request on a production build on a laptop, and about 10 seconds per request on production infrastructure. Three sequential requests triggered load-balancer failover. Because Node.js is single-threaded, the event loop is blocked and other requests queue or time out. Symptoms are CPU saturation, HTTP 503/timeouts and failed health checks that can remove nodes from load balancers. Advisory text also notes out-of-memory exceptions or process termination are possible.

Fix: React changed the logic to traverse the form data once per request, using a bookmark that tracks position and deletes consumed fields, which removes the quadratic behavior. Patched releases are 19.0.6, 19.1.7 and 19.2.6. Red Hat reports no practical mitigation other than upgrading. Defense-in-depth recommended by the source article: POST body-size limits, request-rate controls and timeouts, and monitoring for unusual POST activity against Server Action endpoints.

Context: this follows earlier RSC denial-of-service disclosures (December 2025 DoS and source-code exposure; CVE-2026-23864 in January 2026 for an incomplete fix; CVE-2026-23869 and CVE-2026-23870 in May 2026). Wiz reports the CVE is not in the CISA KEV catalog, with no confirmed in-the-wild exploitation, and a public PoC on GitHub targeting Next.js 16.2.4. No threat actor attribution or network IOCs are published.

## MITRE ATT&CK

- T1594 Search Victim-Owned Websites
- T1587.004 Develop Capabilities: Exploits
- T1190 Exploit Public-Facing Application
- T1499.003 Endpoint Denial of Service: Application Exhaustion Flood
- T1499.004 Endpoint Denial of Service: Application or System Exploitation
- T1592.002 Gather Victim Host Information
- T1588.006 Obtain Capabilities
- T1499 Endpoint Denial of Service

## Sources

- [React Server Components Flaw Lets Attackers Freeze Next.js Servers With a Single POST Request](https://cybersecuritynews.com/react-server-components-dos-vulnerability/)
- [Simon Koeck - React RSC FormData Event Loop DoS write-up](https://simonkoeck.com/writeups/react-rsc-formdata-event-loop-dos)
- [GitHub Security Advisory GHSA-rv78-f8rc-xrxh (facebook/react)](https://github.com/facebook/react/security/advisories/GHSA-rv78-f8rc-xrxh)
- [NVD - CVE-2026-23870](https://nvd.nist.gov/vuln/detail/CVE-2026-23870)
- [Wiz Vulnerability Database - CVE-2026-23870](https://www.wiz.io/vulnerability-database/cve/cve-2026-23870)
- [Red Hat CVE-2026-23870](https://access.redhat.com/security/cve/CVE-2026-23870)
- [ZeroPath - CVE-2026-23870 React Server Components DoS analysis](https://zeropath.com/blog/cve-2026-23870-react-server-components-dos)
- [GitLab Advisory Database - react-server-dom-webpack CVE-2026-23870](https://advisories.gitlab.com/npm/react-server-dom-webpack/CVE-2026-23870/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3096
